MAL-2026-13587Malicious code in dolyame-ui-inputtools (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | dolyame-ui-inputtools | 35.8.1 |
{"modified":"2026-08-07T12:23:40Z","published":"2026-08-07T12:23:40Z","schema_version":"1.7.4","id":"MAL-2026-13587","summary":"Malicious code in dolyame-ui-inputtools (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b19507e10e8c209d60c32cbff9d46f8cc96774c67892192be7550d75064cfb63)\nOn require(), index.js loads _bridge.js which assembles per-platform executable URLs from string-split fragments resolving to rotating Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, cf102-baf, cf99-9b3, cf101-adf) and *.dl.wel1.ru (sdk/ext/pkg/net subdomains), with a DNS TXT covert-channel fallback that reassembles base64 chunks from numbered subdomain TXT records. Downloaded bytes are written to /tmp or %TEMP% under disguised names (.cache_<hex>, dotnet_diag_<hex>.exe), chmod 0755, and spawned detached via cp.spawn(\"/bin/sh\", [\"-c\", fp + \" &\"], {detached:true}).unref(). No hash or signature verification is performed and the destinations are not publisher infrastructure. The same fetch->write->chmod+x->detached-spawn chain is duplicated in lib/telemetry.js (the package's main export), which frames itself as an 'Analytics SDK / observability' module and obfuscates the child_process require via string concatenation (require(\"child_\"+\"process\")) and the fs.chmodSync call via fs[\"chmod\"+\"Sync\"]. The 'ui-inputtools' package name and the telemetry cover story do not match the shipped behavior.\n","affected":[{"package":{"ecosystem":"npm","name":"dolyame-ui-inputtools"},"versions":["35.8.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_bridge.js","sha256":"6aa5c0836332719f6d66ca5553c78e17d82c91fbf68515f89ec504419ae149e9","tlsh":"29a1965a16fa30180692f1d8851f541a719efa833284e9d4fb4c66955f96238c3b29ec"},{"path":"lib/telemetry.js","sha256":"d1fc24218d888a158ca7d1fd4455c6fc0587b34c0d2174e680fd2e4698bd228a","tlsh":"9c73304966fb10214263b0685fab40437635c4072a4eed5dba9c43ec9f8db3896f1fb9"}],"package_integrity":[{"filename":"dolyame-ui-inputtools-35.8.1.tgz","hashes":{"sha1":"020ca5b252a38eeaf471f9a4a0adc278243d8477","sha512_sri":"sha512-k8AvLOKiY/5N6j6PBX0ckoPJX0DFvhC91Om98SEuX4j4RJ+HJ0g4Ys092QVYHfDIiUAsdMoKFBZC1AgTEM1edQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dolyame-ui-inputtools/v/35.8.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016962","import_time":"2026-08-07T12:51:19.932063697Z","modified_time":"2026-08-07T12:23:40Z","sha256":"b19507e10e8c209d60c32cbff9d46f8cc96774c67892192be7550d75064cfb63","source":"amazon-inspector","versions":["35.8.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0